HIGH · 7.2

CVE-2001-0087

itetris/xitetris 1.6.2 and earlier trusts the PATH environmental variable to find and execute the gunzip program, which allows local users to gain root privileges by changing their PATH so that it poi...

Vulnerability Description

itetris/xitetris 1.6.2 and earlier trusts the PATH environmental variable to find and execute the gunzip program, which allows local users to gain root privileges by changing their PATH so that it points to a malicious gunzip program.

CVSS Score

7.2

HIGH

AV:L/AC:L/Au:N/C:C/I:C/A:C
Confidentiality
COMPLETE
Integrity
COMPLETE
Availability
COMPLETE

Affected Products

VendorProductVersions
Michael GlickmanItetris1.6.1

References

FAQ

What is CVE-2001-0087?

CVE-2001-0087 is a vulnerability with a CVSS score of 7.2 (HIGH). itetris/xitetris 1.6.2 and earlier trusts the PATH environmental variable to find and execute the gunzip program, which allows local users to gain root privileges by changing their PATH so that it poi...

How severe is CVE-2001-0087?

CVE-2001-0087 has been rated HIGH with a CVSS base score of 7.2/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2001-0087?

Check the references section above for vendor advisories and patch information. Affected products include: Michael Glickman Itetris.